节点文献

基于Windows的进程监控系统设计与实现

The Design and Application Process Monitoring System Based on Windows

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 常俊宗容余江刘银山

【Author】 Chang Jun,Zong Rong,Yu Jiang,Liu Yinshan (School of Information Science and Engineering,Yunnan University,Kunming,650091,China)

【机构】 云南大学 信息学院

【摘要】 针对目前恶意进程的检测方法漏检率和错检率高,功能单一,没有提供与其它安全事件关联的接口和方法的问题,提出了基于调用线程调度链表例程的隐藏进程检测算法,结合误用检测和异步检测的进程混合检测算法,并实现了一个原型系统——Sanship Windows。通过基于FU_RootKit工具软件的编程接口开发了木马攻击实例,进行了模拟攻击实验,结果显示系统能准确地检测出攻击行为,验证了算法在主机系统中的可行性,为主机系统的安全防御提供了有效的解决方案。

【Abstract】 In order to solve the problems of high omission ratio and miss ratio,too simple function and absence of interfaces with security event correlation,we,through call thread scheduling routines list,propose a hidden process detection algorithm which combines anomaly detection with misuse detection and with which the prototype system Sanship Windows is developed.Simulate attack tests have been made,based on FU_RootKit API,to prove that Sanship Windows can detect attacker correctly,to confirm its feasibility in host system and to provide host security with a significant solution.

【基金】 云南省科技厅重点项目(2008CA004)
  • 【会议录名称】 2010通信理论与技术新发展——第十五届全国青年通信学术会议论文集(下册)
  • 【会议名称】2010通信理论与技术新发展——第十五届全国青年通信学术会议
  • 【会议时间】2010-08-06
  • 【会议地点】中国云南昆明
  • 【分类号】TP393.08
  • 【主办单位】中国通信学会
节点文献中: